409
VMScore

CVE-2019-14584

Published: 03/06/2021 Updated: 11/06/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tianocore edk2

Vendor Advisories

Debian Bug report logs - #977300 CVE-2019-14584 Package: src:edk2; Maintainer for src:edk2 is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 13 Dec 2020 19:00:01 UTC Severity: important Tags: security Forwarded to bugzillatianocoreo ...
A security issue was found in edk2 up to edk2-stable202011 AuthenticodeVerify() calls OpenSSLs d2i_PKCS7() API to parse asn encoded signed authenticode pkcs#7 data When this successfully returns, a type check is done by calling PKCS7_type_is_signed() and then Pkcs7->dsign->contents->type is used It is possible to construct an asn1 blob ...